Niif maintains a narrowly scoped Shibboleth authentication product that serves as a federated identity and access management layer across academic and research institutions, presenting a centralized authentication chokepoint. The recurring vulnerability pattern centers on web-tier input handling, with durable signals in cross-site request forgery and cross-site scripting weaknesses that are characteristic of web-facing authentication systems. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Niif over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-3375MEDIUM Cross-site request forgery (CSRF) vulnerability in the Shibboleth Authentication module before 6.x-4.1 and 7.x-4.x before 7.x-4.1 for Drupal allows remote attackers to hijack the a | Apr 21, 2015 | 5.8 | 16 | NO | NO |
CVE-2012-4494MEDIUM The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restr | Oct 31, 2012 | 4.3 | 16 | NO | NO |
CVE-2009-4527MEDIUM The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other | Dec 31, 2009 | 4.6 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before 7.x-4.2 for Drupal allows remote authenticated users with | Aug 18, 2015 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Niif.
Media articles that mention a CVE ID that affects a product developed by Niif — matched by CVE ID, not by vendor name.